The gist: The update addresses security vulnerabilities in permission previews, errors in subagent model resolution, and critical bugs in parallelization and persistence.
Claude Code 2.1.211 fixes multiple security gaps in permission display as well as stability issues in multi-session scenarios and model selection.
Security improvements: The permission previews forwarded to chat channels now neutralize bidirectional override, zero-width, and look-alike quote characters. This prevents tool inputs from visually corrupting the approval message. Additionally, a bug is fixed where the auto-mode of a PreToolUse hook ask decision ignored unsandboxed Bash — hook asks are now treated as a minimum and enforce a prompt.
Model selection and subagents: Claude Code on Vertex and Bedrock no longer attempts to load the default Opus model on startup when a different model is explicitly configured. Subagents spawned with an explicit model override no longer revert to the parent model on resume or follow-up messages. New additions include a --forward-subagent-text flag and a CLAUDE_CODE_FORWARD_SUBAGENT_TEXT environment variable to include subagent text and thinking in stream JSON output.
Multi-session stability: A bug is fixed where parallel Claude Code sessions would simultaneously log out after wake-from-sleep when many sessions shared a credential store. Plugin MCP servers now reconnect after an idle web session wake, so MCP calls no longer fail until the next message. Background sessions no longer lose their context connection after daemon respawn on LLM gateway auth, and background agents no longer respawn after kill through user action.
Files and UI: File upload validation now accepts filenames with DOS device suffix (.prn) and trailing period, but refuses files with multiple hard links. Edits that leave input as “?” are no longer silently discarded. The Claude in Chrome setup fixes errors when opening setup pages on Windows. Terminal bell is preserved for screen readers after /terminal-setup, and the /clear command now correctly resets the session cost counter to $0.
Performance and API: Async content reveal (settings, stats, diffs) was accelerated from 300ms+. Integer environment variables now accept scientific notation and digit separator notation (e.g. 1e6, 64_000). Permission rules are stored in the repository root so approvals persist across Git worktrees.
Source: github.com · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.